Docker clients send the seccomp profile JSON itself in
HostConfig.SecurityOpt (the docker CLI reads the profile file
client-side and inlines it). The compat API treated the value as a path
to a profile file, so container create failed with "file name too
long". This breaks docker-compat tooling that passes seccomp profiles
through the socket, like Nextcloud AIO and forgejo-runner.
Add a SeccompProfile field to specgen for inline profile content,
next to the existing SeccompProfilePath, as requested in review of the
earlier PR that tried to fix this (#28985). The compat create handler
extracts inline profiles (values starting with "{") from SecurityOpt
and sets the new field. Path-based values and "unconfined" keep their
current meaning, and duplicate seccomp options resolve last-one-wins,
like docker.
Fixes: #27710
Signed-off-by: r-vdp <ramses@well-founded.dev>
Docker documents HostConfig.PidsLimit 0 as unlimited, but runc sets
pids.max=1 for OCI pids.limit 0. Normalize 0 to -1 when building the
OCI spec so native CLI, compat API, and kube play behave consistently.
Fixes: https://github.com/podman-container-tools/podman/issues/29826
Signed-off-by: Jan Rodák <hony.com@seznam.cz>
Docker API v1.44 omits the Created field (previously,
it was the zero value of 0001-01-01T00:00:00Z) if
the Created field is missing from the image config.
Omit it when zero from the compat API GET /images/{id}/json
(using `info.Created` instead of the previous `l.Created()`
that is set to `Now()` in storage/images.go when empty).
Add a test creating an image with the Created field missing.
Fixes: https://redhat.atlassian.net/browse/RUN-3317
Signed-off-by: Marek Simek <msimek@redhat.com>
This is a small Docker compat fix with the API exec endpoints.
With Docker, sending a bare Exec Create (command only, nothing
else set) and then an Exec Start without Detach set performs
a detached exec. With Podman, we threw an error that at least one
stream must be attached to. Fix is trivial; look up the session
before start, check the config for attach streams, and force
detach on if none are set.
Signed-off-by: Matthew Heon <matthew.heon@pm.me>
Fixed the compat container update path so it preserves the existing restart policy unless the request explicitly includes a new one, and added a regression test for it.
Fixes: #29790
Signed-off-by: Srijan Keshri <212402043+arcusbuilds@users.noreply.github.com>
Allow deployments and scheduled jobs to update a selected group of
containers without checking every auto-update-enabled application.
Reuse the existing container filters and expose them through the CLI,
remote bindings, and REST API.
Filter update candidates while preserving systemd unit and pod restart
behavior. Document the selection semantics and cover filtered updates,
invalid input, remote requests, and pod restarts in the existing tests.
Signed-off-by: Evan Purkhiser <git@evanpurkhiser.com>
The Docker-compatible network API omitted the IPRange field from the IPAM
config even though Libpod stores this data, so tools reading the Docker
API could not see the configured IP range.
Map Libpod's LeaseRange to Docker-compatible IPAMConfig.IPRange when it
aligns with a full CIDR span derived from FirstIPInSubnet/LastIPInSubnet,
and add an integration test that creates a network via the compat API with
an explicit IPRange and asserts it is returned on inspect.
The span is matched with bit arithmetic rather than by trying every prefix
length: the network address is start-1, and XORing that with end yields the
host mask, which identifies the prefix in a single pass. net/netip carries
the address handling throughout - Unmap collapses 4-in-6, Prev gives the
network address, and Masked confirms the network is aligned to the prefix.
Fixes: #28378
Signed-off-by: aayushbaluni <73417844+aayushbaluni@users.noreply.github.com>
processMultipartQuadlets previously deferred closing each multipart part
and file inside the loop, leaking descriptors until the handler returned.
It also opened files with os.Create, silently overwriting earlier files if
a request contained parts with duplicate names.
Align processMultipartQuadlets with the manifests multipart upload handler:
- Wrap each part processing in a closure so part and file descriptors close
immediately on each loop iteration.
- Use os.OpenFile with os.O_CREATE|os.O_EXCL|os.O_WRONLY (0600) so duplicate
filenames return an error instead of silently overwriting.
- Sanitize filenames using filepath.Base to prevent directory traversal.
- Add unit tests verifying multiple file extraction, duplicate name rejection,
and path traversal sanitization.
Fixes: #29752
Signed-off-by: Madhosh Yagnik <madhosh1yagnik@gmail.com>
Until now the default could only be expressed by leaving the option off, which
reads as an omission rather than a choice and gives a script no way to say it
wants the archive transferred as podman save wrote it.
Accept none as a format meaning exactly that. It is taken on the API path too,
so both interfaces share one vocabulary, and it is treated as the absence of a
format throughout: nothing is compressed, a level attached to it is rejected the
same way a level with no format is, and the local user to user transfer has
nothing to warn about ignoring.
The remote client still leaves it off the request, so naming the default does
not make a transfer fail against a service that predates these options.
Signed-off-by: Scott Callaway <github@scottcallaway.co.uk>
The tunnel engine builds its own ScpOptions, so without this the flags parse
fine under podman --remote and are then dropped, transferring uncompressed with
no indication that anything was ignored.
Carry both options through the bindings to the libpod ImageScp handler, which
hands them to ExecuteTransfer the same way the local path does, and document
them on the endpoint.
This is also the point at which the transfer's own validation becomes reachable
over HTTP, so map it accordingly: a rejected format or level is the caller's
mistake and answers 400, not the 500 every error from the transfer used to
produce.
Signed-off-by: Scott Callaway <github@scottcallaway.co.uk>
Looks like it picked up new deprecated matches so we need some more
nolint to silence them where we still need them for backwards compat in
the API.
Signed-off-by: Paul Holzinger <pholzing@redhat.com>
Rootless Podman with the cgroupfs manager cannot create a cgroup parent outside its delegated subtree, and container creation already leaves the parent unset there. Reporting "cgroupfs" makes buildx pin its BuildKit container to /docker/buildx, which crun then fails to create with EPERM.
Report "none", as rootless Docker does.
Fixes: #27824
Signed-off-by: Victor Irzak <victor.irzak@zomp.com>
Existing KillContainer handling uses HTTP status code 409 when the request cannot be performed because of the current container state. HTTP status code 404 is also used when the target container does not exist.
In contrast, errors from the stats handler are not reflected in the HTTP status code. The HTTP status code is always 200, and the errors are recorded only as generic errors in the server log.
To maintain compatibility with both streaming enabled and disabled, this change treats obtaining at least one complete unit of response content as the response contract. It then keeps the response content consistent with the HTTP status code.
Signed-off-by: Hiroaki KAWAI <hiroaki.kawai@gmail.com>
Since I use go 1.26 the go fix does not have all the rules built in,
there are newer ones in modernize so run the explicitly to fix more code
for go 1.26.
Signed-off-by: Paul Holzinger <pholzing@redhat.com>
Docker API v1.44 now includes status properties
in Runtimes for the GET /info endpoint.
Read output of {oci_runtime_cmd} features command
lazily and expose the JSON
output as-is (with removed new lines and
whitespace) as the status field in GET
/info for v1.44+.
Add status to libpod GET /info in ociRuntime.features
and `podman info` (shared).
Add API tests for both endpoints.
Fixes: https://redhat.atlassian.net/browse/RUN-3319
Signed-off-by: Marek Simek <msimek@redhat.com>
RestartContainer was always setting options.Timeout with values
from query, without checking if the caller had specified them or if
they were simply zero values. Copy logic from StopContainer to check
for caller-specified values, leaving Timeout nil if not specified.
fixes: https://github.com/podman-container-tools/podman/issues/29276
Signed-off-by: Garry Lawrence <InvalidInterrupt@users.noreply.github.com>
Two commands can set a subject on a manifest list, podman manifest annotate --index --subject and podman manifest add --artifact-subject. Both work locally, but they do nothing at all when podman runs with --remote.
The value never leaves the client. Before sending the request the remote client copies everything into manifests.ModifyOptions and manifests.AddArtifactOptions, and neither struct had a field to hold the subject, so it was quietly thrown away. The server had a second problem of its own, ManifestModify rebuilds ManifestAddArtifactOptions by hand and left out the embedded ManifestAnnotateOptions, so --os, --arch and --annotation were being dropped there as well.
Add the missing field to both structs, fill it in from the tunnel ImageEngine, and let the handler pass the annotate options along. Also add two system tests that run both flags for real so the remote path stays covered.
Signed-off-by: Anisha Khairnar <anishakhairnar284@gmail.com>
When pushing a manifest list, --platform=OS[/Arch[/Variant]] selects and pushes a single platform-specific manifest instead of the entire list.
Also, update compat POST /images/{name}/push to support the platform param (Compat v1.46)
Signed-off-by: Ashley Cui <acui@redhat.com>
The `until` filter was missing from the documentation.
Document it for both GET /libpod/images/json and the
compat GET /images/json.
Add tests for the until filter exercising both endpoints.
Fixes: https://redhat.atlassian.net/browse/RUN-3316
Signed-off-by: Marek Simek <msimek@redhat.com>
When a container has --memory-reservation set without --memory-limit,
resources.Memory is non-nil but resources.Memory.Limit is nil. The
compat stats handler dereferences the nil Limit pointer, causing a
panic that returns a 500 to the client.
Fix: add resources.Memory.Limit != nil guard before the dereference.
Regression test added in test/apiv2/19-stats.at.
Fixes#29627
Signed-off-by: Mehrdad Biukian Naeini <mehrdadbiukian@gmail.com>
filepath.Walk makes an expensive os.Stat system call on every file. filepath.WalkDir uses os.ReadDir under the hood to bypass this overhead, making directory scanning much faster.
Fixes: #29562
Signed-off-by: Vishnu Kothakapu <vishnukothakapu27@gmail.com>